• Dead Peer Detection - Design Flaw and workaround

    Steve Klassen
    Steve Klassen
    Dead Peer Detection has a hidden design flaw. Dead Peer Detection is a feature designed to retry\re-establish a tunnel when a tunnel drops. You can set 3 settings in this feature for 1)how long to wait before a retry, 2)how long to wait for a response…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS IPSec VPN split tunnel

    Simon Hunter
    Simon Hunter
    I am running Sophos XGS 19.5.2 MR-2-Build624 in an active / passive cluster. I have configured IPSec VPN for 150+ remote users. I have approximately 32 split tunnel networks (recently migrated from another vendors platform). I've noticed that once connected…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XG fail with issue "IPsec connection could not be established" with Tunnel interface AWS.

    System Admin12
    System Admin12
    Dear Support; I am using sophos xg firewall hardware device. I do IPSec configuration with AWS according to their configuration file. And follow Sophos Firewall: AWS VPN Gateway IPSEC Connection I received the notice "IPsec connection could not be…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • V19.5.3 and HA-Cluster - VPN Fails "invalid SPI" after upgrading

    juergenb52
    juergenb52
    Hi, i upgraded our XGS2100 from 19.5.2 to 19.5.3 We had a solid VPN Connection to a customer, after upgrading the Connection fails from time to time and VPN Log shows. 2023-08-28 10:11:14 IPSec Deny Received IKE message with invalid SPI (19CBD566…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Site-to-site VPN - Why can't you view your settings when you have a failover group

    Steve Klassen
    Steve Klassen
    Why can't you view your site-to-site settings when you have a failover group active. Whenever I'm working with a SOPHOS engineer on an issue, the first thing they want to do is view the VPN settings, but they can't without taking the VPN tunnel offline…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec Remote Access funktioniert nicht in internem WLAN

    Andreas Debus
    Andreas Debus
    Hallo zusammen, wir haben das Problem, dass sich unser VPN Clients (iOS IPADs mit IPSec VPN) nicht über das interne WLAN verbinden können. von außerhalb funktioniert die Verbindung problemlos. Eine SSL-VPN Verbindung funktioniert Problemlos ist aber…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • VPN IPsec Remote Access - Apipa Gateway on End Devices

    Alejandro Riveros
    Alejandro Riveros
    Hello Everyone, I am enabling IPsec remote access VPN on my firewall XG, the problem is that every time when the clients establish the VPN connection, my clients are getting an Apipa IP address as a gateway and the traffic toward those two IP (172.1…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • VPN Setup

    Dennis Rodriguez
    Dennis Rodriguez
    Hello community. I'm pretty green with setting up VPN's so I have been studying like mad over the last few days every Sophos article and video I could find to try and do this myself but I have hit a brick wall. I need to connect a remote workstation to…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSEC VPN traffic not passing passing through to DST IP

    RyanHosiassohn
    RyanHosiassohn
    Hey All, , So i had something interesting that got fixed today. On the old XG V17-19 when you create a IPSEC VPN, you didnt need to add a no NAT rule (I could be mistaken if some one can confirm this) But on the XGS, I had setup all the VPNs…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Bestimmte Netze routen ueber einen Site2Site Tunnel

    wolfman1
    wolfman1
    Hallo, ich habe folgende Situation: 2x Sophos UTM 2 Standorte verbunden über einen IPsec Site2Site Tunnel, automatic firewall rules enabled Standort 1: 192.168.240.0/24, UTM IP Address 192.168.240.254 Standort 2: 192.168.0.0/24 , UTM IP Address…
    • over 1 year ago
    • UTM Firewall
    • German Forum
  • Ipsec site to site connection

    mulah
    mulah
    im having the problem with ipsec to a client with cisco firewall. The firewall cannot connect to the remote site but the policies and the satting are the same. This is how my setup is Local Public ip : 154.120.225.2 Local ID : set as the Public ip…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Need Help with Client IPSec VPN (Connect) in to Site2Site VPN IPSec Tunnel (Policy Based)

    David Lorenz
    David Lorenz
    Dear Community, my name is david lorenz and I have a problem at one of our customers. At first I will describe my network situation. They have a HQ and a BO. The HQ has the network: 192.168.2.0/24 (Sophos XG210 with 192.168.2.1) The BO has the…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Web Server hinter Site2Site nicht erreichbar

    Jan Esders
    Jan Esders
    Hallo zusammen, leider komme ich mit dem Sophos Support hier nicht oder nur schleppend weiter. Folgende Situatiion: Wir haben eine XGS3100 beim Kunden am Main Office in Betrieb genommen. Daran angebunden sind diverse Standorte hinter einem Site2Site…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • Firewall Drop several initial packet from vpn site to site

    Tri Nguyen2
    Tri Nguyen2
    I have configured an IPSec VPN site-to-site connection between two sites, and after that, the ping traffic was going through between the sites. However, about 10 minutes later, when I pinged again to check, there were always a few initial packets that…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • the received traffic selectors did not match: ::/0 === ::/0

    Anthony Anderson
    Anthony Anderson
    I currently have multiple tunnels on a SFV4C6MSP running on a cloud VM. I use this router to connect multiple IPsec tunnels to different customers. These tunnels are setup as tunnel interfaces. and they will work fine for weeks, or months before one…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS2100 Site-to-Site Tunnel Problem

    Hans-Juergen Guenter
    Hans-Juergen Guenter
    Hallo, ich habe mal eine Frage. Also wie haben zwischen 2 Standorten eine Site-to-Site IPSec VPN Tunnel aufgebaut. Das klappte auch nach ein paar Schwierigkeiten recht gut. Allerdings haben wir nun das Problem, das wenn wir von Standort A nach Standort…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • Route based IPSec traffic stops passing xfrm disabled after pppoe reconnect

    Carlo
    Carlo
    Hello, Every 24 hours after the pppoe connection is reconnected, traffic stops passing through the tunnel. My side is configured as a branch, has a dynamic ip address and initiates an ipsec connection. After the wan ip address is changed, the tunnel…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • IPSec strongswan creating CHILD_SA failed in logs

    Carlo
    Carlo
    Hello, I have IPSec site to site tunnel and I need to troubleshoot why at some point tunnel goes down and or traffic stops flowing. What means this part of log. At the moment tunnel is up and traffic is flowing. Other side has Fortinet firewall, my…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Site to Site VPN Issues Between Sophos XGS 116

    Andre Soares
    Andre Soares
    We are setting up a Site to Site IPSEc VPN between two Sophos XGS 116s. - Is it better to use a pre-shared key or an RSA key? - In the firewall rules, should we put some IPS policy? - In the VPN profile, do we use the IKEv2 protocol? Thanks André…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • site to site VPN

    Meghraj Gholap
    Meghraj Gholap
    Dear Sophos Team, can we setup site to site VPN in same subnet?
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • DNS Request route over IPSec with NAT Translation

    Sven Blanke
    Sven Blanke
    Hallo zusammen, ich habe folgende Problematik und bin dort auf der Suche nach einer Lösung: Wir haben mehrere Branch Office (BO) und binden diese über einen IPSec Tunnel an das Head Office (HO) an. Wir nutzen dazu im IPSec Tunnel das 1:1 NAT um…
    • over 1 year ago
    • Sophos Firewall
    • German Forum
  • How do I connect a NAS that has Wireguard support to Sophos firewall?

    jang430
    jang430
    I am using Unraid NAS on a remote site without public IP. It has support for Wireguard server. I assume there is also a wireguard client. Can this remote NAS connect to my Sophos XG appliance so I can remotely access the remote Unraid NAS? Is this called…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Mysterious logs on all XG's with IPSEC VPN configuration

    Gerd Rehders1
    Gerd Rehders1
    Hi, Since a few days I see the same LOG entry on all XG Firewalls with active IPSEC VPN configuration. (I have checked more than 8 firewalls). The attempts come from the same IP 213.109.84.251 on all machines. Nslookup on this address returns the domain…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos to Smooth wall Site to Site VPN connection

    Jamie Clague
    Jamie Clague
    Anyone in the community has configured Sophos to Smoothwall site-to-site vpn? we have issues establishing the VPN connection between two sites The Details for Phase 1 and Phase 2 are all matching we created firewall rules on both ends the status…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sophos Firewall: Connect Akamai SIA and Sophos Firewall

    DominicRemigio
    DominicRemigio
    Disclaimer : This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment. Table of Contents Overview About Akamai SIA Hardware…
    • over 1 year ago
    • Sophos Firewall
    • Recommended Reads
<>